Arm published a blog post on September 28, 2026 describing how its processor designs underpin NVIDIA's new Open Agent Safety Platform, with Arm-compatible CPUs running AI agents and Arm-based infrastructure processors monitoring and containing them from outside the agent's environment.
Two kinds of compute for agents
Arm argues that agentic AI creates two distinct compute requirements: compute to run the agent, and compute to protect it. The company said agents do not simply generate answers but run continuously, use tools, access data and take actions to complete tasks.
According to the post, Arm supplies both sides of that boundary through high-performance CPUs for agent workloads and Arm-based infrastructure processors such as DPUs that provide "independent observation, isolation, policy enforcement and security".
Arm said AI infrastructure is increasingly moving to its architecture, that Arm technology is deployed across every major hyperscaler, and that, according to IDC, Arm-based rack-scale servers have overtaken x86 as the dominant platform for accelerated computing. That is Arm's characterization of the cited research.
OpenShell on Arm CPUs
Arm described NVIDIA OpenShell as bringing secure agent execution to the broad Arm CPU ecosystem. The company said OpenShell establishes a secure runtime boundary around the agent, governing what it can access and the actions it can take.
The post named the Arm AGI CPU alongside AWS Graviton, Google Axion, Microsoft Cobalt and NVIDIA's custom Vera CPU, which Arm said are architecturally distinct but compatible with the Arm software ecosystem. Arm said the same fundamental approach to secure agent execution can therefore extend across a diverse range of Arm-based cloud and AI infrastructure.
BlueField-4 and Sentry as the control point
Arm said agentic infrastructure also needs independent compute that can observe, isolate and govern policies outside the environment where the agent runs. Moving networking, monitoring, isolation and security off the host CPU, it said, creates a separate control point that stays independent of the agents and applications it protects.
The company pointed to NVIDIA BlueField as a demonstration of that model inside the Open Agent Safety Platform. Arm said BlueField-4 is powered by NVIDIA Grace with 64 Arm Neoverse V2 cores and provides an independent infrastructure environment beyond the host.
OpenShell integrates with NVIDIA Sentry on BlueField to extend policy enforcement from the agent runtime into that separate trust domain, according to Arm. It described Sentry as a real-time watchdog that monitors agent behavior and can quarantine an agent exhibiting unsafe behavior.
What Arm says comes next
Arm said agentic AI will demand more compute as agents become more capable, persistent and autonomous, and that security must scale alongside that compute without forcing a tradeoff.
As agents expand from cloud infrastructure to edge devices and physical systems, Arm said, these security boundaries will need to follow wherever agents run and act. The post is a vendor blog and does not include independent benchmarks, pricing or availability details.
Key facts and where they come from
- Arm says Arm-based rack-scale servers have overtaken x86 for accelerated computing, citing IDC.
Arm-based rack-scale servers have now overtaken x86 as the dominant platform for accelerated computing, according to IDC.
- Arm frames agentic AI as needing compute to run agents and compute to protect them.
As agents scale, they create two fundamental compute requirements: compute to run the agent, and compute to protect the agent.
- OpenShell creates a secure runtime boundary constraining agent access and actions.
OpenShell establishes a secure runtime boundary around the agent, governing what it can access and the actions it can take.
- BlueField-4 uses NVIDIA Grace with 64 Arm Neoverse V2 cores.
BlueField-4, powered by NVIDIA Grace with 64 Arm Neoverse V2 cores, provides an independent infrastructure environment beyond the host.
- NVIDIA Sentry monitors agent behavior and can quarantine unsafe agents.
NVIDIA Sentry is a real-time watchdog that adds another layer, monitoring agent behavior and enabling an agent exhibiting unsafe behavior to be quarantined.
- OpenShell links with Sentry on BlueField to push policy enforcement into a separate trust domain.
OpenShell integrates with NVIDIA Sentry on BlueField to extend policy enforcement from the agent runtime into this separate trust domain
- Arm lists Graviton, Axion, Cobalt and Vera as Arm-ecosystem-compatible CPUs.
AWS Graviton, Google Axion, Microsoft Cobalt, and NVIDIA’s custom Vera CPU all architecturally distinct but compatible with the Arm software ecosystem
